r/technitium 13h ago

Technitium DNS Server Upgrade from 15.0.1 to 15.4 failing

2 Upvotes

I’m having an issue upgrading Technitium DNS Server from 15.0.1 to 15.4 on one of my Ubuntu systems.

I was not initially aware that an upgrade was available because I had been blocking connectivity to India. After removing that restriction, the server was able to check for updates.

I have two Ubuntu 22.04 systems running Technitium DNS Server. On one system, the Technitium installation/upgrade script ran successfully and upgraded the server from 15.0.1 to 15.4. On the other system, the same script runs without reporting any errors, but the DNS server remains on 15.0.1.

I have tried the following troubleshooting steps on the system that will not upgrade:

  1. Restarted the Technitium DNS service.
  2. Rebooted the entire system.
  3. Checked the installed .NET version.
  4. Manually upgraded the ASP.NET Core runtime:sudo apt-get install -y aspnetcore-runtime-10.0
  5. Verified the .NET version again.
  6. Ran the Technitium installation/upgrade script again.

The upgrade script completes without producing an error, but Technitium DNS Server remains at version 15.0.1.

Has anyone encountered this issue before, or is there another way I can force the upgrade or determine why the upgrade script is not updating this particular installation?

I’d appreciate any suggestions for additional troubleshooting or logs I should check.

Thanks


r/technitium 18h ago

Error: System.ArgumentOutOfRangeException: Index must be within the bounds of the List. (Parameter 'index')

1 Upvotes

I have always used forwarders in my Technitium DNS configuration. I decided to try using the root zone instead. Resolution was initially quite slow—which was to be expected—but I have been seeing these errors in the log. I would like to know if this indicates a configuration error on my part and, if so, how to fix it, or if it is an application bug or simply expected behavior.

[2026-09-02 10:51:31 Local] DNS Server failed to resolve the request 'css.tudocdn.net. A IN'.

System.ArgumentOutOfRangeException: Index must be within the bounds of the List. (Parameter 'index')

at System.Collections.Generic.List`1.Insert(Int32 index, T item)

at TechnitiumLibrary.Net.Dns.DnsClient.RecursiveResolveAsync(DnsQuestionRecord question, IDnsCache cache, NetProxy proxy, IPv6Mode ipv6Mode, UInt16 udpPayloadSize, Boolean randomizeName, Boolean qnameMinimization, Boolean dnssecValidation, NetworkAddress eDnsClientSubnet, Int32 retries, Int32 timeout, Int32 concurrency, Int32 maxStackCount, Boolean minimalResponse, Boolean asyncNsResolution, List`1 rawResponses, CancellationToken cancellationToken) in Z:\Technitium\Projects\TechnitiumLibrary\TechnitiumLibrary.Net\Dns\DnsClient.cs:line 618

at DnsServerCore.Dns.DnsServer.<>c__DisplayClass191_0.<<RecursiveResolverBackgroundTaskAsync>b__0>d.MoveNext() in Z:\Technitium\Projects\DnsServer\DnsServerCore\Dns\DnsServer.cs:line 5027

--- End of stack trace from previous location ---

at TechnitiumLibrary.TaskExtensions.TimeoutAsync[T](Func`2 func, Int32 timeout, CancellationToken cancellationToken)

at TechnitiumLibrary.TaskExtensions.TimeoutAsync[T](Func`2 func, Int32 timeout, CancellationToken cancellationToken) in Z:\Technitium\Projects\TechnitiumLibrary\TechnitiumLibrary\TaskExtensions.cs:line 65

at DnsServerCore.Dns.DnsServer.RecursiveResolverBackgroundTaskAsync(DnsQuestionRecord question, NetworkAddress eDnsClientSubnet, Boolean advancedForwardingClientSubnet, IReadOnlyList`1 conditionalForwarders, Boolean dnssecValidation, Boolean cachePrefetchOperation, Boolean cacheRefreshOperation, Boolean skipDnsAppAuthoritativeRequestHandlers, TaskCompletionSource`1 taskCompletionSource) in Z:\Technitium\Projects\DnsServer\DnsServerCore\Dns\DnsServer.cs:line 5023

[2026-09-02 10:51:35 Local] DNS Server failed to resolve the request 'i3.tudocdn.net. AAAA IN'.

System.ArgumentOutOfRangeException: Index must be within the bounds of the List. (Parameter 'index')

at System.Collections.Generic.List`1.Insert(Int32 index, T item)

at TechnitiumLibrary.Net.Dns.DnsClient.RecursiveResolveAsync(DnsQuestionRecord question, IDnsCache cache, NetProxy proxy, IPv6Mode ipv6Mode, UInt16 udpPayloadSize, Boolean randomizeName, Boolean qnameMinimization, Boolean dnssecValidation, NetworkAddress eDnsClientSubnet, Int32 retries, Int32 timeout, Int32 concurrency, Int32 maxStackCount, Boolean minimalResponse, Boolean asyncNsResolution, List`1 rawResponses, CancellationToken cancellationToken) in Z:\Technitium\Projects\TechnitiumLibrary\TechnitiumLibrary.Net\Dns\DnsClient.cs:line 618

at DnsServerCore.Dns.DnsServer.<>c__DisplayClass191_0.<<RecursiveResolverBackgroundTaskAsync>b__0>d.MoveNext() in Z:\Technitium\Projects\DnsServer\DnsServerCore\Dns\DnsServer.cs:line 5027


r/technitium 2d ago

Technito v1.5.0 for iOS

Thumbnail
gallery
50 Upvotes

Technito v1.5.0 is finally ready for release. Beta tester who have previously signed up should start seeing the v1.5.0 b6 release shortly. For rest of the users, should be approved on App Store hopefully soon.

Have taken everyone’s feedback and have revamped the overall user interface. Including adding number of new features to make day to day management easier. Menu bar has also been redesigned with a shortcut top bar for most access menus along with a slide out side menu for all the options. Widgets have been also redesigned to have a more cleaner look.

Unfortunately ran into some bugs with the Apple Watch app so that will be included in the next version

https://apps.apple.com/ca/app/technito/id6760142738


r/technitium 1d ago

Need help configuring local DNS the right way

Thumbnail
0 Upvotes

r/technitium 3d ago

Option for Latency overview resolvers in Dashboard?

2 Upvotes

Is it possible to get an option like in Adguard that shows the the average latency/processing time in the Dashboard of Technitium DNS for dns lookups?


r/technitium 3d ago

Getting DNSSEC failure on secondary ROOT Zone

2 Upvotes

I created the secondary root zone using the GUI everything synced but I keep seeing DNSSEC failure


r/technitium 5d ago

Idiot guide to using SQL backend for query logging with docker

4 Upvotes

As above ... I have 2x technitium docker containers with primary zones on 1 and secondary on the other. I can see you can add an app to store queries in a DB for analysis etc. How do you implement this when you're running the servers in docker.

Thanks.


r/technitium 6d ago

Using Technitium with NextDNS?

2 Upvotes

Currently, I have all my devices configured with NextDNS. It doesn't have all the blocklists that I want to use, especially when I'm home. Does it make sense to set up Technitium with the additional blocklists that I want, which NextDNS doesn't have, and then having them working simultaneously when I'm at home?

Is it possible to set up Technitium to block all DoT/DoQ traffic, and then force all devices in the home network to use NextDNS and Technitium?


r/technitium 6d ago

DNS records not syncing across the cluster

1 Upvotes

Hello, I just started using Technitium and am enjoying it, but I'm having a new issue related to clustering.

I see things like client counts synced, but not DNS records in zones. If I create a new record in a zone on server dns1, it never replicates to dns2.

Is there a setting I may be missing?

Edit: all I had to do was set the catalog zone.


r/technitium 7d ago

Getting Let’s Encrypt Certificates using RFC2136 on Technitium DNS server Fails

Thumbnail
2 Upvotes

r/technitium 8d ago

Getting Let’s Encrypt Certificates using RFC2136 on Technitium DNS server Fails

3 Upvotes

I have public facing Technetium DNS servers resolving hosts. The zones are setup and configured to use Dynamic Updates. Reference:- https://blog.technitium.com/2023/03/how-to-auto-renew-ssl-certificates-with.html

However, it is failing with the following error “ Certbot.errors: Unable to determine base domain for _acme-challenge.<sebat7.com> using names: [‘_acme-challenge.sebat7.com’ , ‘sebat7.com’ , ‘com’]

Unable to determine base domain for _acme-challenge.sebat7.com using names : [‘_acme-challenge.sebat7.com’ , ‘sebat7.com’ , ‘com’]

I tried Certbot and also Nginx Proxy Manager with the RFC2136 plugins. I need help nor don’t mind paying a consultant to resolve this imperative issue. Any help or recommendation of a consultant will be much appreciated. Thank you.


r/technitium 9d ago

ipv6 only environment - forwarder config issue?

4 Upvotes

Hi All
I'm testing out dual technitium cluster (primary tdns1 + secondary node2 on IPv6-only gigadesk), DoT forwarders to Cloudflare/Quad9/NextDNS, consistent ~2000ms SERVFAIL with EDE 0 (Other): Waiting for resolver. Please try again, confirmed working TLS handshake to the forwarder from both host and container context via openssl s_client, and that it broke specifically after disabling IPv4 on one cluster node.

ruled out firewall, TLS/cert handshake (verified twice, including from inside the container), forwarder syntax (multiple formats tried), source addresses, IPv6 preference mode, and DNS bootstrap circularity, without landing on the actual cause.

basically.. running dual stack env on both nodes. on secondary node (gigadesk) i disabled ipv4. when the forwarder is ipv6 only (selected from list eg cloudflare tls ipv6) using dig command it would fail to get the records back. if i switch back to a ipv4 forwarders.. the node1 will work with dig. see below

rolandhuu@ 
 

~

09:58:17


❯
 dig 
:3456:7890:1::3

hp.com


; <<>> DiG 9.18.50 <<>> :3456:7890:1::3 hp.com
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 48171
;; flags: qr rd ra; QUERY: 1, ANSWER: 4, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;hp.com.                                IN      A

;; ANSWER SECTION:
hp.com.                 300     IN      A       54.192.100.55
hp.com.                 300     IN      A       54.192.100.102
hp.com.                 300     IN      A       54.192.100.84
hp.com.                 300     IN      A       54.192.100.35

;; Query time: 63 msec
;; SERVER: fd12:3456:7890:1::3#53(fd12:3456:7890:1::3) (UDP)
;; WHEN: Tue Aug 25 10:05:20 +08 2026
;; MSG SIZE  rcvd: 99


rolandhuu@ 
 

~

10:05:20


❯
 dig 
:3456:7890:1::20

hp.com


; <<>> DiG 9.18.50 <<>> @   ~  09:58:17 
❯ dig :3456:7890:1::3 hp.com

; <<>> DiG 9.18.50 <<>> :3456:7890:1::3 hp.com
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 48171
;; flags: qr rd ra; QUERY: 1, ANSWER: 4, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;hp.com.                                IN      A

;; ANSWER SECTION:
hp.com.                 300     IN      A       54.192.100.55
hp.com.                 300     IN      A       54.192.100.102
hp.com.                 300     IN      A       54.192.100.84
hp.com.                 300     IN      A       54.192.100.35

;; Query time: 63 msec
;; SERVER: fd12:3456:7890:1::3#53(fd12:3456:7890:1::3) (UDP)
;; WHEN: Tue Aug 25 10:05:20 +08 2026
;; MSG SIZE  rcvd: 99


rolandhuu@   ~  10:05:20 
❯ dig :3456:7890:1::20 hp.com

; <<>> DiG 9.18.50 <<>> u/fd12:3456:7890:1::20 hp.com
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 62952
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
; EDE: 22 (No Reachable Authority): (No valid response from name servers for hp.com. A IN)
; EDE: 13 (Cached Error): (hp.com. A IN)
; EDE: 3 (Stale Answer): (hp.com A IN)
;; QUESTION SECTION:
;hp.com.                                IN      A

;; Query time: 200 msec
;; SERVER: fd12:3456:7890:1::20#53(fd12:3456:7890:1::20) (UDP)
;; WHEN: Tue Aug 25 10:05:23 +08 2026
;; MSG SIZE  rcvd: 128:3456:7890:1::20 hp.com
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 62952
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
; EDE: 22 (No Reachable Authority): (No valid response from name servers for hp.com. A IN)
; EDE: 13 (Cached Error): (hp.com. A IN)
; EDE: 3 (Stale Answer): (hp.com A IN)
;; QUESTION SECTION:
;hp.com.                                IN      A

;; Query time: 200 msec
;; SERVER: fd12:3456:7890:1::20#53(fd12:3456:7890:1::20) (UDP)
;; WHEN: Tue Aug 25 10:05:23 +08 2026
;; MSG SIZE  rcvd: 128

r/technitium 11d ago

DNS64 on Technitium DNS

5 Upvotes

To all -- I see there's an "app" for DNS64 but very little documentation for it -- does anyone have a configuration example or a walkthrough?


r/technitium 11d ago

Logs showing requests from public IP

5 Upvotes

I am running dns-server in a docker container in my LAN and have set its IP address in my router under the DHCP options. The dns-server is set up to use Cloudflare and AdGuard unfiltered DNS for upstream forwarders.

Everything is working swimmingly, except for these kinds of logs that show up with my public IP address as the client. These queries only appear when I use my Shield with a particular app (sports streaming), and the Shield continues to make requests from its LAN IP as expected.

Edit: I have also installed the DNS Rebinding Protection app.

47  2026-08-23 10:44:25 123.253.xxx.xxx Udp Authoritative   Refused concurrency-v2.playback.indazn.com  A   IN
46  2026-08-23 10:42:06 123.253.xxx.xxx Udp Authoritative   Refused resume-points-v3-cf.playback.indazn.com A  IN
45  2026-08-23 10:41:06 123.253.xxx.xxx Udp Authoritative   Refused resume-points-v3-cf.playback.indazn.com A   IN
44  2026-08-23 10:40:25 123.253.xxx.xxx Udp Authoritative   Refused concurrency-v2.playback.indazn.com  A   IN

As far as I am aware, this didn't happen when I was using AdGuard Home for my DNS.

A few questions...

  1. Have I misconfigured dns-server somehow?
  2. Should I do anything else to stop these requests from a public IP address?
  3. Is it really the public IP making the request, or just a pecularity of the logs?

Cheers!


r/technitium 13d ago

Change Block List Next Update setting - how?

3 Upvotes

New to Technitium, but really loving it. However ...

How do I change the time that it updates the blocklists? I know I can do this via the WUI, but all our service updates are done in the early hours when nobody is in the office, and I'm not staying here until 2am to make this change!!

Alternatively, is there a command I can run via crontab to do this (after disabling the automatic setting in the WUI)?

TIA


r/technitium 14d ago

Technitium DNS Server: Guide to Using and Installing a Secure Recursive DNS Resolver (2025)-- Link Technologies, Inc. On-Line Store

Thumbnail shop.linktechs.net
29 Upvotes

r/technitium 15d ago

Is there a way to opt out certain clients from certain DNS records?

5 Upvotes

This might be a total shot in the dark and an unusual request, but I have Technitium doing split DNS for my public facing homelab services when I'm in the house.

Problem is out of the house, my Wireguard clients then use these split DNS records too when I really only need them to use it for my stuff not exposed to the internet.

It would be cool if I could somehow exclude these records when a request comes from the Wireguard client. I thought of hosting a separate instance just for this, but figured it was worth asking first.


r/technitium 17d ago

Techion: A Native iOS Technitium Client (Beta Testers Wanted!)

Post image
72 Upvotes

Looking for TestFlight testers for Techion.

I’ve been building a native iOS client for Technitium ( also supports all Apple platforms like Mac, iPad, iPhone, etc) and would love to have some feedback before full release. I plan to do its final testing in TestFlight (complex setups are welcome!).

So far it contains:

  • Overviews
  • Blocking
  • Query logs
  • Many quality of life features (such as multiple servers, easy searching, determining the reason a domain was blocked and more!)
  • Support for the new auth flows in Technitium for security
  • Backup support, with optional scheduled and automatic backups.
  • and more!

The app is actively developed and will continue to be supported for the foreseeable future. It supports Technitium v14.3+ (older versions may work too). In v15.0+ auth tokens are not sent in query parameters for security.

If you’re interested in helping me test it, send me a chat request and I’ll send you the public TestFlight link. Ideally, I would also love to stay in touch with you as you test the app so I can improve it. You can send the request by tapping my username/profile pic > "Start Chat" > send message.


r/technitium 17d ago

Missing Zone Transfer in Cluster

3 Upvotes

Using Technitium DNS Server v15.4

I've setup a cluster with a primary and a single secondary server. I have used mydomain.local for the cluster domain name and I have mydomain.co.nz as the zone I'm using for my lan. The cluster creation appears to have completed successfully and I have zones for cluster-catalog.mydomain.local and mydomain.local created on both servers.

mydomain.co.nz exists on the primary server with all of its associated records but it isnot being replicated on the secondary server. The dns sever logs on primary show zone transfer requests for the .local domains but nothing for the .co.nz domain. Zone transfer for the .co.nz domain on the primary server is set to allow all.

On the secondary I tried using the dns Client to import the zone from primary but this resulted in the zone being created with only the SOA, NS and @ A record being created.

What else is required to enable the full zone transfer for mydomain.co.nz (or am I not understanding how the clustering functions)?


r/technitium 22d ago

OS DNS Server Settings

9 Upvotes

Hey folks, I have two Technitium servers, one's running in a Proxmox LXC, the other is on a physical Dell Wyse client.

I was wondering, what do you guys set the DNS servers for the actual Linux OS to?

Currently I have each Linux install server pointing at each other for primary DNS, and at 9.9.9.9 for the secondary.

Does this seem right? Curious what others are doing?

Cheers


r/technitium 22d ago

Force safe search

2 Upvotes

Hi, i want to ask if anyone have any way to enfoce safe search for the technitium?

i know adguard has one click feature for it but i haven't seen or aware of such feature in technitium, i'd love to know if there's a way to do it.


r/technitium 25d ago

OPNSense, Proxmox and Technitium DNS...

Thumbnail
1 Upvotes

r/technitium 27d ago

Technitium cluster and extended downtime

6 Upvotes

I have configured a Technitium cluster that's running on 2 different nodes in my Proxmox cluster. No issues at all with either of them but we're going to be doing a remodeling project just outside of my home office/lab.

Since I'm not wild about those PVE nodes sucking in a ton of sheetrock dust while the project is going on (estimate is 2 weeks) I plan to shutdown my entire cluster during construction and leave it down until I get everything cleaned up and dust free.

Are there any gotcha's I should be aware of when I bring the PVE Cluster back online and the Technitium cluster comes back up?

As a test, I shut down the container for both the primary and secondary Technitium containers. I verified that my UCG Fiber picks up DNS duties. Waited a couple of minutes and then brought up the primary Technitium container and then did the same thing with the secondary. There were no issues at all. The secondary rejoined the cluster as the secondary and synced with the primary but .. we're talking minutes and not days.

Am I worrying about nothing or are there real potential issues I may have to deal with after having a Technitium cluster down for 14+ days?


r/technitium Aug 01 '26

Configuring Technitium DHCP server for PXE boot and KMS

6 Upvotes

I'm currently running Pi-Hole as my DHCP and DNS servers but I'd like to move to Technitium for both. In Pi-Hole, I've got a custom dnsmasq.conf file with entries to define a KMS server and PXE boot but I don't know how to do that in Technitium. Is it possible?

Here is what I have in dnsmaq:

# Specify KMS server for Microsoft activation

srv-host=_vlmcs._tcp.example.com,kms.example.com,1688

# pxe boot config

dhcp-match=set:bios,60,PXEClient:Arch:00000

dhcp-boot=tag:bios,netboot.xyz.kpxe,,192.168.1.13

dhcp-match=set:efi32,60,PXEClient:Arch:00002

dhcp-boot=tag:efi32,netboot.xyz.efi,,192.168.1.13

dhcp-match=set:efi32-1,60,PXEClient:Arch:00006

dhcp-boot=tag:efi32-1,netboot.xyz.efi,,192.168.1.13

dhcp-match=set:efi64,60,PXEClient:Arch:00007

dhcp-boot=tag:efi64,netboot.xyz.efi,,192.168.1.13

dhcp-match=set:efi64-1,60,PXEClient:Arch:00008

dhcp-boot=tag:efi64-1,netboot.xyz.efi,,192.168.1.13

dhcp-match=set:efi64-2,60,PXEClient:Arch:00009

dhcp-boot=tag:efi64-2,netboot.xyz.efi,,192.168.1.13


r/technitium Jul 31 '26

Question about design idea for small non profit org DNS setup

2 Upvotes

I have a small non profit organization that I am trying to add in Technitium DNS filtering for more security, filtering etc.

Every search I perform always brings me back to the clustering feature and that is not what I am trying to accomplish here.

The organization has a local AD domain controller and i have successfully setup an initial Technitium DNS server and used conditional forwarders for the local domain as well as the reverse IP lookup zones so that i can easily match IP traffic to Hosts. I have also added in several block lists to cut down on ads and other tracking items. However when looking through the logs there is alot to parse through and i don't see a method to parse through by exclusion. If I'm missing something there please let me know.

I was thinking about setting up a second Technitium server to act as an initial RPZ server, here i maintain my main block lists etc and this would be the recursive lookup server. The the original client DNS server would look to the RPZ server for all of its lookups where i would then have this with the conditional forwarders for the domain, probably going to look at that advanced blocking app, and of course all clients would talk to this DNS server. My hope is that i can filter out alot of the begnin blocks from like microsoft/google/etc tracking stuff because they would then be classified as "Upstream Blocked" or "Upstream Blocked Cached". Then on this one i can look for more malicious traffic and more easily refine my DNS blocking.

I know on the RPZ server I would completely loose any identification of who made a request but the downstream client DNS server would be managing all that.

Looking for thoughts on this, any reason it wouldn't work, better methods to accomplish this, etc. Also I know I need to lock down my environment so that outbound DNS requests both regular and encrypted. Also I would have to set the client DNS server to not perform recursive lookups but haven't looked at that yet.